AI Workspace Loading

We’re preparing your intelligent learning experience. Our AI systems are processing content, optimizing resources, and setting everything up for you.

Preparing Learning Paths...
AI Processing
Smart Automation
Learning Engine
Good things take a moment.

LearnLess.ai

LEARN LESS. UNDERSTAND MORE.
Intermediate3 min read

MCP Resources

MCP resources are the data or content an MCP server exposes for a client to read as context.

Prerequisites

Resources vs. Tools

An MCP server exposes two different kinds of things: tools, which perform an action, and resources, which are read-only content a client can pull in as context — a file, a database record, a piece of internal documentation. The distinction matters because reading a resource has no side effects, while calling a tool might.

MCP Tool

Performs an action

May have side effects

Invoked with arguments

MCP Resource

Read-only content

No side effects

Retrieved directly

How Resources Are Used

  • An agent can pull a relevant resource into its context before generating a response, similar in spirit to retrieval in a RAG system — but sourced through an MCP server instead of a vector database.
  • Because resources have no side effects, they're generally lower-risk to expose than tools — though the content itself can still be sensitive and needs the same access-control consideration as any other data source.
  • A server can expose many resources; a client typically lists what's available and reads specific ones as needed, rather than pulling everything at once.

Warning

Content read from an MCP resource still enters the model's context as external data — the same prompt injection considerations apply as with any other retrieved content.

Common Mistakes

  • Confusing resources with tools

    Resources are read-only content with no side effects; tools perform actions — mixing up the two misrepresents the actual risk profile of each.

  • Assuming resources are automatically safe because they're read-only

    No side effects doesn't mean the content is trustworthy — text read from a resource can still carry injected instructions, the same as any retrieved content.

  • Not applying access control to resources

    A resource can expose sensitive content just as easily as a tool can perform a sensitive action — it deserves the same access-control discipline.

  • Pulling in every available resource regardless of relevance

    Like over-retrieving in RAG, reading unnecessary resources crowds the context window without adding useful information.

Interview Question

What is an MCP resource, and how is it different from an MCP tool?

An MCP resource is read-only content an MCP server exposes — a file, a database record, documentation — that a client can pull in as context, distinct from a tool, which performs an action and may have side effects. An agent typically lists available resources and reads specific ones as needed, similar in spirit to retrieval in a RAG system but sourced through an MCP server. Being read-only makes resources generally lower-risk than tools, but it doesn't make them automatically safe — the content itself can still be sensitive and needs the same access control, and text read from a resource still enters the model's context as external data subject to the same prompt injection considerations as any retrieved content.

What an interviewer may ask next

  • Why does the read-only nature of a resource not make it automatically safe to expose?
  • How is reading an MCP resource similar to retrieval in a RAG system?
  • Why might you apply access control to resources the same way you would to tools?

Explain It in 30 Seconds

An MCP resource is read-only content an MCP server exposes — like a file or database record — that a client can pull in as context, distinct from a tool, which performs an action with possible side effects. Being read-only makes resources generally lower-risk, but not automatically safe: the content can still be sensitive and needs access control, and it still enters the model's context as external data subject to the same prompt injection considerations as any retrieved content.

On this page